Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38jf-hjrq-x3rc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a request containing the username, password, and confirmPassword parameters.

modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a request containing the username, password, and confirmPassword parameters.

EPSS

Процентиль: 87%
0.03558
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
почти 12 лет назад

modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a request containing the username, password, and confirmPassword parameters.

EPSS

Процентиль: 87%
0.03558
Низкий

Дефекты

CWE-20